# Phase 1.0S: official shsrv/hbldr provenance Status: `BIGAPP_CONTEXT_SOURCE_PROVEN_DEPLOYED_IDENTITY_UNPROVEN_DEVICE_PATH_BLOCKED` Date: 2026-07-22 This phase acquired and inspected only the official public `ps5-payload-dev/shsrv` Git source. No downloaded code was built or executed. No PS5 address was used, no connection or request was made, and no target source, target artifact, transfer package, installation package, or device client was created. ## Provenance boundary The official repository is `https://github.com/ps5-payload-dev/shsrv`. During the audit its `master`, latest release tag `v0.19`, and commit all resolved to `6f320637d56d344a0e7797753099e33238bbf146`; the tree object is `c26ce02b6c3ca4202993e039b3db7c28c353dee4`. The clean, detached historical `v0.7` worktree resolves to commit `74287f5db6b20320efd7892d7b29cf438fe7cb98` and tree `7184968c702afe038551bf3228cc25f455388bb6`. These source identities prove official implementations, not which shsrv binary—if any—is installed or running on the target PS5. No locally supplied shsrv/hbldr binary, package receipt, deployment log, or byte-exact device identity was found. The deployed identity remains `UNPROVEN`. ## Why v0.7 and v0.19 are both relevant The Phase-1.0Q LakeSnes source at commit `a2db690123649c7ffbc68a663af31efb3a41bf3f` states that shsrv v0.7 or later is required and launches the emulator with `hbldr`. Therefore v0.7 is the oldest source-bound implementation relevant to that port documentation. Version v0.19 is the latest official release inspected during Phase 1.0S. The `hbldr` family began at commit `4a70b50eecab853408f0a93a579b90428369fa09` as an experimental loader that injects an ELF into a web application. The significant lineage is: | Point | Commit/tag | Source-proven behavior | |---|---|---| | introduction | `4a70b50eecab853408f0a93a579b90428369fa09` | inject an ELF into a webapp process | | LakeSnes minimum | `v0.7`, `74287f5...` | launch VideoPlayer BigApp `PPSA01659`, replace its process image | | fake-game transition | `18e9a62aea801b5a1be4a692dba76bf5381e9fcb` | attach homebrew to a created fake game | | first release containing transition | `v0.8` | fake-app/system-ex path present | | current official release | `v0.19`, `6f32063...` | launch `FAKE00000`, replace its process image | An official tag or source lineage is not deployed-use proof. The current device may use no shsrv, a historical build, a current build, or a modified binary. ## Exact source identities ### v0.19 | File | Size | SHA-256 | |---|---:|---| | `README.md` | 3,546 | `4855fa2adbe1fc0c7aa0174aa3275742d9b9aba3d818ae09cf2722a89b06cd34` | | `shsrv.c` | 5,293 | `6ec71b4eb6c2bc1159f21568c1c9834f8aecac8d8881113bf09cf8981be19ee3` | | `sh.c` | 13,278 | `3c4b7f76efdd157436ed4b353ee1b550bf3ff9df17c147b4762b767982fc8253` | | `elfldr.c` | 17,911 | `4aa31f5a942681f8d88281b9713f087ced8963de842438cacad1088933f8e785` | | `bundles/hbldr/main.c` | 1,520 | `6fa519888f79fe0458a983a517073c1eccc61239edfbe40d607f69b6b38a8af4` | | `bundles/hbldr/hbldr.c` | 13,438 | `0096f86a00fdedcbc7509db47eb0f54dbc3e487d37e699f3de79048bac001be9` | ### v0.7 | File | Size | SHA-256 | |---|---:|---| | `README.md` | 3,248 | `3d16e46416dd07940fcde1190a6ab558348bc80263da615331dda0f3eb6183ed` | | `shsrv.c` | 4,716 | `66197d08308180fe923aa8aedc91bd5025f08938156ae3092ea2c69d0ad0be57` | | `sh.c` | 8,449 | `bf97bc6dd3f49345ad8da9a29b28a5d6bcde5e53a6f32c60a538d6e187c7e05a` | | `elfldr.c` | 17,920 | `1ff6cfa1300a95e8be48e5f7adc1413e3384ba04ea266c167fcd441ef20197d1` | | `bundles/hbldr/main.c` | 7,134 | `2081ece2f7d0a7e9b392660696c2a44802f64680365607e742b37dcf3223a55a` | ## PacBrew relationship PacBrew commit `c2abcfcb60f569128abd0e8e70ad03a67bee5ea7` contains an shsrv recipe that clones the official repository, uses `pkgver=git`, and declares `sha256sums=('SKIP')`. It installs `shsrv.elf`, but does not pin the fetched shsrv commit or prove which package was installed on the target. It is `SOURCE_REPOSITORY_ASSOCIATION`, not byte-exact deployment provenance. ## Proven and unproven conclusions `SOURCE_PROVEN`: - the official hbldr family creates or launches a BigApp and replaces that process with the requested ELF; - v0.7 and v0.19 differ materially from raw elfldr's SceSpZeroConf process; - both variants read the target ELF from a device path; - both may terminate the currently running BigApp and perform kernel/ptrace process mutations; - v0.19 may remount and persistently populate `/system_ex/app/FAKE00000`. `UNPROVEN`: - which shsrv/hbldr binary is deployed; - whether `FAKE00000` already exists on the target; - whether the launcher works on the specific firmware-9.60 runtime; - whether BigApp substitution provides the missing VideoOut permission; - whether it would make the exact RetroArch first submit succeed; - crash, cleanup, reboot, and visibility behavior on the target. The source difference is a `STRONG_SOURCE_CANDIDATE_NOT_PROVEN_ROOT_CAUSE`. It does not authorize using hbldr, staging an ELF, connecting to shsrv, or creating a replacement launcher.